CVE-2015-0557
EPSS 3.4%
Description
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.
How to fix CVE-2015-0557
To remediate CVE-2015-0557, upgrade the affected package to a fixed version below.
- Debian/arj—upgrade to 3.10.22-13 or later
Is CVE-2015-0557 being exploited?
Low — EPSS is 3.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.10.22-13